GPG
KEY GENERATION#
gpg --gen-key # Generate key (interactive) gpg --full-gen-key # Full key generation options gpg --quick-gen-key "Name <email>" # Quick key generation gpg --quick-gen-key "Name <email>" rsa4096 # RSA 4096-bit key
KEY MANAGEMENT#
gpg --list-keys # List public keys (gpg -k) gpg --list-secret-keys # List private keys (gpg -K) gpg --list-keys --keyid-format long # Show long key IDs gpg --fingerprint # Show key fingerprints gpg --fingerprint user@email.com # Fingerprint for specific key gpg --delete-key KEY_ID # Delete public key gpg --delete-secret-key KEY_ID # Delete private key gpg --edit-key KEY_ID # Edit key (interactive)
EXPORT KEYS#
gpg --export -a "Name" > public.asc # Export public key (ASCII) gpg --export KEY_ID > public.gpg # Export public key (binary) gpg --export-secret-keys -a "Name" > private.asc # Export private key gpg --export-secret-keys KEY_ID > private.gpg # Export private key (binary) gpg --export-ownertrust > trust.txt # Export trust database
IMPORT KEYS#
gpg --import public.asc # Import public key gpg --import private.asc # Import private key gpg --import-ownertrust trust.txt # Import trust database
KEY SERVERS#
gpg --keyserver hkps://keys.openpgp.org --send-keys KEY_ID # Upload key gpg --keyserver hkps://keys.openpgp.org --recv-keys KEY_ID # Download key gpg --keyserver hkps://keys.openpgp.org --search-keys "email" # Search keys gpg --refresh-keys # Refresh all keys from server # Common keyservers hkps://keys.openpgp.org hkps://keyserver.ubuntu.com hkps://pgp.mit.edu
TRUST LEVELS#
gpg --edit-key KEY_ID
trust # Set trust level
1 = unknown
2 = never trust
3 = marginally trust
4 = fully trust
5 = ultimately trust
save # Save and exit
ENCRYPTION#
# Encrypt for recipient gpg -e -r recipient@email.com file # Encrypt file gpg --encrypt --recipient KEY_ID file # Using key ID gpg -e -r recipient1 -r recipient2 file # Multiple recipients gpg -e -r recipient@email.com -a file # ASCII output (.asc) # Symmetric encryption (password only) gpg -c file # Encrypt with passphrase gpg --symmetric file # Same as above gpg -c --cipher-algo AES256 file # Specify cipher # Encrypt and sign gpg -e -s -r recipient@email.com file # Encrypt and sign gpg --encrypt --sign -r KEY_ID file # Long form
DECRYPTION#
gpg -d file.gpg # Decrypt to stdout gpg --decrypt file.gpg # Same as above gpg -d file.gpg > output # Decrypt to file gpg -o output -d file.gpg # Specify output file gpg --decrypt --output output file.gpg # Long form
SIGNING#
gpg -s file # Sign (binary) gpg --sign file # Same as above gpg --clearsign file # Sign (readable text) gpg -b file # Detached signature gpg --detach-sign file # Same as above gpg -a -b file # ASCII detached signature gpg --local-user KEY_ID -s file # Sign with specific key
SIGNATURE VERIFICATION#
gpg --verify file.sig # Verify detached signature gpg --verify file.sig file # Verify against specific file gpg --verify file.asc # Verify signed file gpg -d file.gpg # Decrypt and verify
COMMON OPTIONS#
-a, --armor # ASCII armored output -o, --output FILE # Output to file -r, --recipient USER # Encrypt for user -u, --local-user USER # Use specific key for signing -v, --verbose # Verbose output --batch # Non-interactive mode --yes # Assume yes to questions --no # Assume no to questions --passphrase STRING # Provide passphrase
PIPING & STDIN#
echo "secret" | gpg -e -r email -a # Encrypt from stdin cat file | gpg -e -r email > file.gpg gpg -d file.gpg | less # Decrypt to pager echo "secret" | gpg -c -a # Symmetric from stdin
REVOCATION#
gpg --gen-revoke KEY_ID > revoke.asc # Generate revocation cert gpg --import revoke.asc # Revoke key (import cert)
SUBKEY MANAGEMENT#
gpg --edit-key KEY_ID addkey # Add subkey key 1 # Select subkey 1 delkey # Delete selected subkey expire # Change expiration passwd # Change passphrase save # Save and exit
CONFIGURATION (~/.gnupg/gpg.conf)#
default-key KEY_ID keyserver hkps://keys.openpgp.org personal-cipher-preferences AES256 AES192 AES personal-digest-preferences SHA512 SHA384 SHA256 cert-digest-algo SHA512 default-preference-list SHA512 SHA384 SHA256 AES256 AES192 AES ZLIB BZIP2 ZIP no-emit-version no-comments keyid-format 0xlong with-fingerprint
AGENT MANAGEMENT#
gpg-connect-agent reloadagent /bye # Reload agent gpg-agent --daemon # Start agent gpgconf --kill gpg-agent # Kill agent echo RELOADAGENT | gpg-connect-agent # Reload agent
PRACTICAL EXAMPLES#
# Create encrypted backup tar czf - directory/ | gpg -e -r email > backup.tar.gz.gpg # Decrypt and extract gpg -d backup.tar.gz.gpg | tar xzf - # Sign git commits git config --global user.signingkey KEY_ID git config --global commit.gpgsign true # Verify downloaded file gpg --verify file.sig file.tar.gz # Encrypt for multiple recipients gpg -e -r user1@email.com -r user2@email.com secret.txt # Create ASCII armored signed message gpg --clearsign message.txt
SECURITY BEST PRACTICES#
- Use 4096-bit RSA or Ed25519 keys - Set key expiration (1-2 years) - Store revocation certificate securely offline - Use subkeys for daily operations - Backup master key securely - Use hardware tokens for high security (YubiKey)
TROUBLESHOOTING#
# Fix permission errors chmod 700 ~/.gnupg chmod 600 ~/.gnupg/* # Clear passphrase cache gpgconf --reload gpg-agent # Debug issues gpg --verbose --verbose file.gpg # Check GPG version gpg --version
GPG CHEATSHEET
==============
Source: https://cheatsheet.johlem.net
KEY GENERATION
--------------
gpg --gen-key # Generate key (interactive)
gpg --full-gen-key # Full key generation options
gpg --quick-gen-key "Name <email>" # Quick key generation
gpg --quick-gen-key "Name <email>" rsa4096 # RSA 4096-bit key
KEY MANAGEMENT
--------------
gpg --list-keys # List public keys (gpg -k)
gpg --list-secret-keys # List private keys (gpg -K)
gpg --list-keys --keyid-format long # Show long key IDs
gpg --fingerprint # Show key fingerprints
gpg --fingerprint user@email.com # Fingerprint for specific key
gpg --delete-key KEY_ID # Delete public key
gpg --delete-secret-key KEY_ID # Delete private key
gpg --edit-key KEY_ID # Edit key (interactive)
EXPORT KEYS
-----------
gpg --export -a "Name" > public.asc # Export public key (ASCII)
gpg --export KEY_ID > public.gpg # Export public key (binary)
gpg --export-secret-keys -a "Name" > private.asc # Export private key
gpg --export-secret-keys KEY_ID > private.gpg # Export private key (binary)
gpg --export-ownertrust > trust.txt # Export trust database
IMPORT KEYS
-----------
gpg --import public.asc # Import public key
gpg --import private.asc # Import private key
gpg --import-ownertrust trust.txt # Import trust database
KEY SERVERS
-----------
gpg --keyserver hkps://keys.openpgp.org --send-keys KEY_ID # Upload key
gpg --keyserver hkps://keys.openpgp.org --recv-keys KEY_ID # Download key
gpg --keyserver hkps://keys.openpgp.org --search-keys "email" # Search keys
gpg --refresh-keys # Refresh all keys from server
# Common keyservers
hkps://keys.openpgp.org
hkps://keyserver.ubuntu.com
hkps://pgp.mit.edu
TRUST LEVELS
------------
gpg --edit-key KEY_ID
trust # Set trust level
1 = unknown
2 = never trust
3 = marginally trust
4 = fully trust
5 = ultimately trust
save # Save and exit
ENCRYPTION
----------
# Encrypt for recipient
gpg -e -r recipient@email.com file # Encrypt file
gpg --encrypt --recipient KEY_ID file # Using key ID
gpg -e -r recipient1 -r recipient2 file # Multiple recipients
gpg -e -r recipient@email.com -a file # ASCII output (.asc)
# Symmetric encryption (password only)
gpg -c file # Encrypt with passphrase
gpg --symmetric file # Same as above
gpg -c --cipher-algo AES256 file # Specify cipher
# Encrypt and sign
gpg -e -s -r recipient@email.com file # Encrypt and sign
gpg --encrypt --sign -r KEY_ID file # Long form
DECRYPTION
----------
gpg -d file.gpg # Decrypt to stdout
gpg --decrypt file.gpg # Same as above
gpg -d file.gpg > output # Decrypt to file
gpg -o output -d file.gpg # Specify output file
gpg --decrypt --output output file.gpg # Long form
SIGNING
-------
gpg -s file # Sign (binary)
gpg --sign file # Same as above
gpg --clearsign file # Sign (readable text)
gpg -b file # Detached signature
gpg --detach-sign file # Same as above
gpg -a -b file # ASCII detached signature
gpg --local-user KEY_ID -s file # Sign with specific key
SIGNATURE VERIFICATION
----------------------
gpg --verify file.sig # Verify detached signature
gpg --verify file.sig file # Verify against specific file
gpg --verify file.asc # Verify signed file
gpg -d file.gpg # Decrypt and verify
COMMON OPTIONS
--------------
-a, --armor # ASCII armored output
-o, --output FILE # Output to file
-r, --recipient USER # Encrypt for user
-u, --local-user USER # Use specific key for signing
-v, --verbose # Verbose output
--batch # Non-interactive mode
--yes # Assume yes to questions
--no # Assume no to questions
--passphrase STRING # Provide passphrase
PIPING & STDIN
--------------
echo "secret" | gpg -e -r email -a # Encrypt from stdin
cat file | gpg -e -r email > file.gpg
gpg -d file.gpg | less # Decrypt to pager
echo "secret" | gpg -c -a # Symmetric from stdin
REVOCATION
----------
gpg --gen-revoke KEY_ID > revoke.asc # Generate revocation cert
gpg --import revoke.asc # Revoke key (import cert)
SUBKEY MANAGEMENT
-----------------
gpg --edit-key KEY_ID
addkey # Add subkey
key 1 # Select subkey 1
delkey # Delete selected subkey
expire # Change expiration
passwd # Change passphrase
save # Save and exit
CONFIGURATION (~/.gnupg/gpg.conf)
---------------------------------
default-key KEY_ID
keyserver hkps://keys.openpgp.org
personal-cipher-preferences AES256 AES192 AES
personal-digest-preferences SHA512 SHA384 SHA256
cert-digest-algo SHA512
default-preference-list SHA512 SHA384 SHA256 AES256 AES192 AES ZLIB BZIP2 ZIP
no-emit-version
no-comments
keyid-format 0xlong
with-fingerprint
AGENT MANAGEMENT
----------------
gpg-connect-agent reloadagent /bye # Reload agent
gpg-agent --daemon # Start agent
gpgconf --kill gpg-agent # Kill agent
echo RELOADAGENT | gpg-connect-agent # Reload agent
PRACTICAL EXAMPLES
------------------
# Create encrypted backup
tar czf - directory/ | gpg -e -r email > backup.tar.gz.gpg
# Decrypt and extract
gpg -d backup.tar.gz.gpg | tar xzf -
# Sign git commits
git config --global user.signingkey KEY_ID
git config --global commit.gpgsign true
# Verify downloaded file
gpg --verify file.sig file.tar.gz
# Encrypt for multiple recipients
gpg -e -r user1@email.com -r user2@email.com secret.txt
# Create ASCII armored signed message
gpg --clearsign message.txt
SECURITY BEST PRACTICES
-----------------------
- Use 4096-bit RSA or Ed25519 keys
- Set key expiration (1-2 years)
- Store revocation certificate securely offline
- Use subkeys for daily operations
- Backup master key securely
- Use hardware tokens for high security (YubiKey)
TROUBLESHOOTING
---------------
# Fix permission errors
chmod 700 ~/.gnupg
chmod 600 ~/.gnupg/*
# Clear passphrase cache
gpgconf --reload gpg-agent
# Debug issues
gpg --verbose --verbose file.gpg
# Check GPG version
gpg --version
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.